Back

HIGH

kernel: Null pointer dereference via keyctl

Published Nov 28, 2016

Description

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.

Affected products

Remediation

Red Hat statement

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7, MRG-2 and realtime kernels. This issue does not affect kernels that ship with Red Hat Enterprise Linux 5.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 28, 2016
Updated Aug 6, 2024
Reserved Oct 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 15, 2016